Open by Default After AI: The GDS Guidance and the Enforcement Question
AI Cybersecurity Classified by Officially
In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated vulnerability discovery. The actual effect was to contradict years of established UK government open source policy with no public consultation, no published threat model, and no evidence the closures removed any meaningful attacker advantage.
On 14 May 2026, the Government Digital Service (GDS) and the Department for Science, Innovation and Technology (DSIT) issued guidance titled AI, Open Code and Vulnerability Risk in the Public Sector. It is a direct, technically grounded rebuttal. The guidance reaffirms open by default as the correct posture for publicly-funded code and makes it clear that closing repositories to compensate for poor security hygiene, or a misguided belief in security by obscurity is not an acceptable practice.
This brief summarizes what the guidance says, why the NHS England decision was wrong on its own terms, and what both mean for the international open source security community.
Background: What NHS England Did and Why It Matters
NHS England removed public access to repositories following vulnerabilities reported to it through Anthropic’s Project Glasswing, an initiative giving a limited set of organisations access to Claude Mythos Preview for defensive security work. AISI’s April 2026 evaluation of that model found it capable of discovering and exploiting vulnerabilities autonomously in controlled conditions.
The community response was fast. A petition at keepthingsopen.com crossed 2,000 signatures within days. Former NHSX Head of Open Technology Terence Eden, who helped build the open source and open standards policies NHS England is now reversing, described the decision as a non-technical management overreaction to a threat briefing. He has filed a Freedom of Information request for the internal deliberations.
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/blog/2026/09/10/open-by-default-after-ai-the-gds-guidance-and-the-enforcement-question/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 2 recorded
- Identity
https://openssf.org/?p=11696